Template. This document must be reviewed and completed by counsel before it is relied on. Questions: hello@humxn.io
01Introduction and incorporation
This Data Processing Addendum ("DPA") forms part of the agreement between HUMXN Data Labs ("HUMXN" or "Processor") and the customer identified in the applicable order form ("Customer" or "Controller") for the provision of HUMXN's services (the "Agreement").
This DPA applies where and to the extent that the Processor processes Customer Personal Data on behalf of the Customer in the course of providing the services. If there is a conflict between this DPA and the Agreement, this DPA prevails with respect to the processing of Customer Personal Data. If there is a conflict between this DPA and the Standard Contractual Clauses, the Standard Contractual Clauses prevail.
02Definitions
Capitalized terms not defined in this DPA have the meanings given in the Agreement. In this DPA:
- "Data Protection Laws" means all laws applicable to the processing of Customer Personal Data under the Agreement, including Regulation (EU) 2016/679 (the "GDPR"), the GDPR as it forms part of UK law and the UK Data Protection Act 2018 ("UK GDPR"), the Swiss Federal Act on Data Protection, and the California Consumer Privacy Act as amended ("CCPA"), in each case as applicable.
- "Customer Personal Data" means personal data that the Processor processes on behalf of the Customer under the Agreement.
- "Controller", "Processor", "Data Subject", "Personal Data", "Processing", "Personal Data Breach" and "Supervisory Authority" have the meanings given in the GDPR, and "Service Provider" and "Business" have the meanings given in the CCPA.
- "Sub-processor" means any third party engaged by the Processor to process Customer Personal Data.
- "Standard Contractual Clauses" or "SCCs" means the standard contractual clauses annexed to Commission Implementing Decision (EU) 2021/914, and "UK Addendum" means the International Data Transfer Addendum issued by the UK Information Commissioner under section 119A of the Data Protection Act 2018.
03Roles of the parties
The Customer is the controller and the Processor is the processor of Customer Personal Data. Where the Customer acts as a processor on behalf of a third-party controller, the Processor is a sub-processor, and the Customer confirms that its instructions have been authorized by the relevant controller.
Each party will comply with the obligations that apply to it under Data Protection Laws. The Customer is responsible for the lawfulness of the Customer Personal Data it provides and of its instructions, including having an appropriate legal basis and providing any required notices.
For Personal Data that HUMXN processes for its own purposes, such as managing member accounts, billing, verifying contributor consent and maintaining provenance records, HUMXN acts as an independent controller and this DPA does not apply to that processing.
04Processing on documented instructions
The Processor will process Customer Personal Data only on the Customer's documented instructions, including with regard to international transfers, unless required to do so by applicable law. In that case the Processor will inform the Customer of that legal requirement before processing, unless the law prohibits this on important grounds of public interest.
The Agreement, this DPA, the order form and the Customer's configuration and use of the services constitute the Customer's complete instructions. Additional instructions must be agreed in writing. The Processor will promptly inform the Customer if, in its opinion, an instruction infringes Data Protection Laws.
Where the CCPA applies, the Processor will not sell or share Customer Personal Data, will not retain, use or disclose it outside the direct business relationship or for any purpose other than performing the services, and will not combine it with personal information received from other sources except as permitted by the CCPA.
05Confidentiality of personnel
The Processor will ensure that persons authorized to process Customer Personal Data, including employees, contractors and experts, are bound by appropriate obligations of confidentiality, receive training appropriate to their role, and access Customer Personal Data only to the extent necessary to perform the services.
06Security of processing
Taking into account the state of the art, the costs of implementation and the nature, scope, context and purposes of processing, as well as the risks to the rights and freedoms of natural persons, the Processor will implement and maintain appropriate technical and organizational measures to protect Customer Personal Data, as required by Article 32 GDPR.
The measures in place at the date of this DPA are described on HUMXN's Security page and in security documentation available to the Customer under NDA on request. The Processor may update its measures over time, provided that updates do not materially reduce the overall level of protection.
07Sub-processors
The Customer gives general authorization for the Processor to engage Sub-processors. The current list is published on HUMXN's Sub-processors page.
The Processor will give the Customer at least [30] days' notice before a new Sub-processor begins processing Customer Personal Data, by updating the Sub-processors page and notifying Customers who have subscribed to updates or by email. The Customer may object on reasonable grounds relating to data protection within that notice period. The parties will discuss the objection in good faith; if they cannot resolve it, the Customer may terminate the affected services and receive a pro-rata refund of prepaid fees for the terminated portion.
The Processor will impose on each Sub-processor, by written contract, data protection obligations that provide at least the same level of protection as this DPA, and remains liable to the Customer for each Sub-processor's performance of those obligations.
08Assistance with data subject requests
Taking into account the nature of the processing, the Processor will assist the Customer by appropriate technical and organizational measures, insofar as possible, in fulfilling its obligations to respond to requests from Data Subjects exercising their rights under Data Protection Laws.
If the Processor receives a request directly from a Data Subject relating to Customer Personal Data, it will promptly forward the request to the Customer without responding, other than to direct the Data Subject to the Customer, unless otherwise required by law.
09Assistance with impact assessments and consultations
Taking into account the nature of the processing and the information available to it, the Processor will provide reasonable assistance to the Customer with data protection impact assessments and prior consultations with Supervisory Authorities that the Customer is required to carry out under Articles 35 and 36 GDPR, to the extent they relate to the Processor's processing of Customer Personal Data.
Assistance beyond making available documentation that the Processor maintains for its customers generally may be subject to reasonable fees agreed in advance.
10Personal Data Breach notification
The Processor will notify the Customer without undue delay after becoming aware of a Personal Data Breach affecting Customer Personal Data, and in any event within [48] hours.
The notification will, to the extent known, describe the nature of the breach including the categories and approximate number of Data Subjects and records concerned, the likely consequences, and the measures taken or proposed to address the breach and mitigate its effects. Where information is not available at once, it will be provided in phases without further undue delay.
The Processor will take reasonable steps to contain, investigate and remediate the breach and will cooperate with the Customer in meeting its notification obligations. Notification is not an acknowledgment of fault or liability.
11International transfers
The Processor will not transfer Customer Personal Data outside the EEA, the UK or Switzerland except in compliance with Data Protection Laws.
To the extent a transfer of Customer Personal Data from the EEA to a country without an adequacy decision occurs under this DPA, the SCCs are incorporated by reference, using Module Two (controller to processor) or Module Three (processor to processor) as applicable. For the SCCs: Clause 7 (docking clause) applies; under Clause 9 option 2 (general authorization) applies with the notice period in this DPA; the optional language in Clause 11 does not apply; Clauses 17 and 18 are governed by and subject to the courts of [EU Member State]; and Annexes I and II are completed by the Annex to this DPA and the Security page.
For transfers from the UK, the UK Addendum is incorporated and completed with the information in this DPA, and for transfers from Switzerland, the SCCs apply with the modifications required by Swiss law. The Processor will implement supplementary measures where needed and will make its transfer impact assessment available on request.
12Information and audits
The Processor will make available to the Customer the information reasonably necessary to demonstrate compliance with Article 28 GDPR, including its security documentation, which will be shared under NDA on request.
If that information is not sufficient to demonstrate compliance, or where required by a Supervisory Authority, the Customer may, at its own cost and no more than once in any 12-month period (except following a Personal Data Breach or a regulator's request), conduct an audit, either itself or through an independent auditor bound by confidentiality who is not a competitor of the Processor. The Customer will give at least [30] days' written notice, and the parties will agree the scope, timing and duration in advance to minimize disruption and protect the confidentiality of other customers' data.
13Return and deletion
On termination or expiry of the services, the Processor will, at the Customer's choice, return Customer Personal Data to the Customer or delete it, and delete existing copies within [30] days, unless applicable law requires further storage.
Data held in backups will be deleted in accordance with the Processor's backup rotation schedule and protected in the meantime under this DPA. Where retention is legally required, the Processor will continue to protect the data and process it only for the purpose of that retention. On request, the Processor will confirm deletion in writing.
14Liability
Each party's liability arising out of or relating to this DPA, whether in contract, tort or otherwise, is subject to the limitations and exclusions of liability in the Agreement, except to the extent such limitations are not permitted under Data Protection Laws or the SCCs. [Any data-protection-specific liability cap or carve-out to be agreed.]
15Term and general provisions
This DPA remains in effect for as long as the Processor processes Customer Personal Data on behalf of the Customer. It is governed by the law that governs the Agreement, except where Data Protection Laws or the SCCs require otherwise. If any provision is found invalid, the remainder continues in effect.
To request a countersigned copy of this DPA, contact legal@humxn.io.
16Annex: Description of processing
This Annex describes the processing of Customer Personal Data and serves as Annex I.B to the SCCs where they apply. Details for a specific engagement may be supplemented in the order form.
- Subject matter: provision of HUMXN's services, including sourcing, verifying, labeling, reviewing, packaging and delivering datasets, and any processing of Customer-supplied data as specified in the order form.
- Duration: the term of the Agreement plus the period until deletion or return of Customer Personal Data in accordance with this DPA.
- Nature of processing: collection, recording, organization, storage, hashing and fingerprinting, screening for safety and personal data, masking, labeling, expert review, retrieval, transmission, and deletion.
- Purpose: to provide the services under the Agreement and the Customer's documented instructions, and to provide related support.
- Categories of Personal Data: contact and account details of the Customer's authorized users (name, work email, role); communications and support records; usage and audit logs; and any personal data contained in Customer-supplied data or briefs, as specified in the order form. [Special categories, if any, to be specified with applicable restrictions; none are expected by default.]
- Categories of Data Subjects: the Customer's employees, contractors and authorized users; individuals whose personal data is contained in data the Customer supplies; and other individuals specified in the order form.
- Frequency of transfer: continuous for the duration of the services.
- Sub-processors: as listed on the Sub-processors page, for the subject matter, nature and duration described there.
- Competent Supervisory Authority: [Supervisory authority determined in accordance with Clause 13 of the SCCs].

